You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-query-results.md
+33-14Lines changed: 33 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,10 +32,11 @@ appliesto:
32
32
33
33
While you can construct your [advanced hunting](advanced-hunting-overview.md) queries to return precise information, you can also work with the query results to gain further insight and investigate specific activities and indicators. You can take the following actions on your query results:
34
34
35
-
- View results as a table or chart
36
-
- Export tables and charts
37
-
- Drill down to detailed entity information
38
-
- Tweak your queries directly from the results
35
+
-[View results as a table or chart](#view-query-results-as-a-table-or-chart)
36
+
-[Export tables and charts](#export-tables-and-charts)
37
+
-[Drill down to detailed entity information](#drill-down-from-query-results)
38
+
-[Tweak your queries directly from the results](#tweak-your-queries-from-the-results)
39
+
-[View timeline of events](#automatic-timeline-rendering)
39
40
40
41
## View query results as a table or chart
41
42
@@ -202,44 +203,62 @@ By default, a timeline appears above the advanced hunting results that displays
202
203
203
204
:::image type="content" source="/defender/media/advanced-hunting-query-results-timeline.png" alt-text="Screenshot of the timeline above the query results in advanced hunting." lightbox="/defender/media/advanced-hunting-query-results-timeline.png":::
204
205
205
-
You can select whether or not the timeline is displayed by default in the **Page preferences** settings.
206
+
You can select whether or not the timeline is displayed by default in the **Chart preferences** settings.
206
207
207
-
:::image type="content" source="/defender/media/advanced-hunting-page-preferences.png" alt-text="Screenshot of the Page preferences settings in advanced hunting." lightbox="/defender/media/advanced-hunting-page-preferences-zoom.png":::
208
+
:::image type="content" source="/defender/media/advanced-hunting-chart-preferences.png" alt-text="Screenshot of the Page preferences settings in advanced hunting." lightbox="/defender/media/advanced-hunting-chart-preferences.png":::
208
209
209
-
The timeline automatically adjusts its resolution based on the range of results. You can click any point on the timeline to filter both the results and the timeline to that specific time range. The timeline also updates its scale to match the selected time period, so when you filter by a specific range, it zooms in to show event distribution in high resolution.
210
+
The timeline automatically adjusts its resolution based on the range of results.
210
211
211
-
The timeline only appears if there are more than 40 events in your results and there's `Timestamp` or `timeGenerated` column.
212
+
### Filter the timeline results
212
213
213
-
### [Unfiltered timeline](#tab/unfiltered)
214
+
Select any point on the timeline to filter both the results and the timeline to that specific time range. The timeline also updates its scale to match the selected time period, so when you filter by a specific range, it zooms in to show event distribution in high resolution.
215
+
216
+
#### [Unfiltered timeline](#tab/unfiltered)
214
217
215
218
The following screenshot shows the results of a query that returns 1,000 email events. The timeline is unfiltered, so it displays the full range of results with a timestamp for each day. Select a day or range of days to filter the results for that time period.
216
219
217
220
:::image type="content" source="/defender/media/advanced-hunting-unfiltered-results.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with all the results unfiltered." lightbox="/defender/media/advanced-hunting-unfiltered-results.png":::
218
221
219
-
### [Filtered timeline](#tab/filtered)
222
+
####[Filtered timeline](#tab/filtered)
220
223
221
224
The following screenshot shows the zoomed in results of a query filtered to a specific date.
222
225
223
226
:::image type="content" source="/defender/media/advanced-hunting-filtered-results.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results filtered to a specific date." lightbox="/defender/media/advanced-hunting-filtered-results.png":::
224
227
225
228
---
226
229
227
-
You can group the results in the timeline by any column that has at least two but less than 50 unique values.
230
+
### Split the timeline by values
231
+
232
+
You can split the results in the timeline by any column that has at least two but less than 50 unique values.
228
233
229
-
### [Ungrouped timeline](#tab/ungrouped)
234
+
####[Ungrouped timeline](#tab/ungrouped)
230
235
231
236
The following screenshot shows the results of a query that returns 1,000 email events. The timeline is ungrouped, so it displays all the results in a single line.
232
237
233
238
:::image type="content" source="/defender/media/advanced-hunting-ungrouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results all together in one line." lightbox="/defender/media/advanced-hunting-ungrouped.png":::
234
239
235
-
### [Grouped timeline](#tab/grouped)
240
+
####[Grouped timeline](#tab/grouped)
236
241
237
242
The following screenshot shows the results grouped by last email action with a separate line for each action.
238
243
239
-
:::image type="content" source="/defender/media/advanced-hunting-grouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results grouped by last email action." lightbox="/defender/media/advanced-hunting-grouped-zoom.png":::
244
+
:::image type="content" source="/defender/media/advanced-hunting-grouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results grouped by last email action." lightbox="/defender/media/advanced-hunting-grouped.png":::
240
245
241
246
---
242
247
248
+
### Change chart type
249
+
250
+
You can change the chart type of the timeline by selecting a different option from the chart type dropdown menu. The available chart types include:
251
+
252
+
- Column chart
253
+
- Pie chart
254
+
255
+
### Rendering conditions
256
+
257
+
The timeline only appears if the following conditions are met:
0 commit comments